| CVE | Icon | Vulnerability name | Date | Responsible Security Disclosure by | Stars | Process | Vulnerabilities |
|---|---|---|---|---|---|---|---|
| - | LdapBindBleed | 2026-09-27 | kta1kri | Responsible disclosure through private GitHub advisory GHSA-m87f-f43w-hwmc, with a detailed report and suggested fix; validated and fixed by xet7. | LDAP direct user-bind mode accepted empty passwords. On a directory that permits unauthenticated binds and the subsequent user search, this could authenticate a matching WeKan account without its password. Both user-authentication helpers and the DDP/REST login boundary now reject empty or malformed credentials before binding or falling back. CWE-287. Conditional critical authentication bypass. No CVE assigned. The OpenLDAP administrator guide states that unauthenticated binds are disabled by default; the report’s stock-default claim was not confirmed. Fix prepared for the Upcoming release. |
Blocked attempts are summarized as LdapBindBleed in Admin Panel / Problems. Passwords are never included in the security event.
Source fix and regression coverage
The actual LDAP class and login handler were reproduced with controlled directory and database responses. Tests cover valid and wrong passwords, empty and non-string credentials, both modes, ambiguous searches, local fallback, logging failure and intentional anonymous service searches. Chromium verifies that an empty-password attempt creates no session and records a Problems summary.
The authentication regression run passed 46 focused Node suites and five Chromium scenarios. The local Meteor application rebuilt successfully. Live OpenLDAP/Active Directory, external CAS/SAML providers, Sandstorm and the FerretDB authentication matrix were not tested.